CiberLATAMbywhalemate

Brazil tightens data and Pix fraud controls

Brazil’s central bank is revising open finance rules and speeding up Pix safeguards with AI, standard alerts and bank-to-bank sharing.

Whalemate Labs · AI-assisted researchPublished:4 min read

Brazil’s central bank is revising partnership rules in open finance to tighten customer data controls and standardize consent under the LGPD. At the same time, it is preparing a fraud-probability indicator for each Pix transaction, along with mandatory alerts, automatic information sharing between banks and tougher precautionary measures.

Brazil’s central bank is working on a review of partnership rules in open finance to tighten customer data controls and standardize consent under the LGPD and the open finance framework itself. At the same time, it is moving ahead with a security agenda for Pix that includes a fraud-probability indicator for each transaction, calculated in real time with machine learning and made available to participating institutions.

What changes in open finance?

The review is intended to clarify how consent for the use of personal data is obtained and managed, with a standard format aligned with the Lei Geral de Proteção de Dados. According to Mardilson Queiroz, head of regulation at the central bank, the goal is to strengthen control over customer information within ecosystem partnerships.

That move comes as sector-specific analysis in Brazil notes that financial institutions must maintain technical and administrative safeguards for personal data, along with cybersecurity policies and vulnerability management. In practice, the regulatory review overlaps with compliance duties already covering banks, fintechs and other system participants.

What tools will Pix add?

The central bank’s agenda includes a fraud-probability indicator for each Pix transaction, calculated in real time with machine learning and shared with institutions so they can feed their own detection systems. It also calls for mandatory standardization of fraud alerts, which are now used unevenly across entities.

The plan also foresees a direct and automated flow of information between banks to enable precautionary blocks on suspicious transactions. In addition, the central bank is considering a broader set of precautionary measures for institutions that compromise the system’s operation, including restrictions on registering new Pix keys.

How does the protection scheme come together?

Pix protection also relies on the evolution of the Mecanismo Especial de Devolução into MED 2.0. That tool can trace later transfers beyond the first destination account, identify accounts potentially involved in the movement of illicit funds and notify institutions so they can block balances and review suspicious activity.

At the same time, materials for banks and fintechs say the central bank requires internal control and compliance structures capable of preventing fraud and money laundering, with direct implications for access governance over systems and sensitive data. Those obligations connect to the Lei de Lavagem de Dinheiro nº 9.613/1998 and the Lei Anticorrupção nº 12.846/2013.

The Federal Senate has received PL 2006/2026, which proposes measures to prevent, identify, contain, trace and suppress the illicit use of bank and payment accounts in fraud and other financial crimes. The bill seeks to strengthen monitoring and response obligations for financial institutions and payment service providers.

The discussion is unfolding alongside recent changes to the Penal Code that explicitly criminalize handing over a conta laranja, with penalties of 1 to 5 years in prison and a fine. In that context, tougher penalties for those who facilitate accounts used in money-laundering schemes and digital scams are moving in parallel with the bill’s progress in the Senate.

What else is moving in compliance and third parties?

Analysis of Brazil’s financial sector also says the requirements in CMN Resolutions No. 4,893/2021 and No. 5,274/2025 apply to data processing and storage services, as well as cloud computing. That directly ties cybersecurity policy to IT outsourcing and the management of critical technology vendors.

In the same vein, specialized publications note that the central bank also frames these obligations within internal control and compliance structures that must support fraud and money-laundering prevention. The result is a broader regulatory model that connects personal data, operational security, transaction monitoring and third-party risk management.

Sources

View all